Menu

IoT FEATURE NEWS

CIS Controls Says Its Best Practices Could Prevent Equifax-style Breach

By

The Equifax breach and the others that have recently gotten headlines are relevant to all cybersecurity practices, especially in the IoT where we have fallen behind the mark several times on the security front.

According to CIS, a non-profit entity that harnesses the power of the global IT community to safeguard private and public organizations against cyber threats, attacks such as WannaCry and Equifax could have been prevented with a diligent implementation of its CIS Control 4: “Continuous Vulnerability Assessment and Remediation.” CIS Control 4 calls for IT managers to assess enterprise vulnerabilities on a regular basis, typically using automated tools, and fixing most critical vulnerabilities. It may be that Equifax also failed to properly inventory all of their hardware and software (CIS Controls 1 and 2) as well as conduct monitoring and analysis of audit logs (CIS Control 6).

Equifax has acknowledged its recent incident occurred due to the exploitation of a known vulnerability that had been identified in March 2017 as part of Apache's software called “Struts.” This vulnerability had been identified as a critical vulnerability, and a remedy was provided by Apache almost immediately. The May 2017 WannaCry cyber-attack was a similar story in that the ransomware in this case exploited another known vulnerability, this time in the Windows operating system. Most other high-profile breaches follow the same pattern: failure to implement basic cyber hygiene.

“Unfortunately, the Equifax breach is yet another example of what can happen if organizations are not vigilant about foundational cyber practices such as patching known vulnerabilities,” said Tony Sager, SVP and Chief Evangelist for the CIS Controls, CIS.

The CIS Controls were developed through a consensus process to prioritize essential technical actions all organizations should take to protect their systems and networks. They represent a foundational list of specific actions that can be used to implement the higher-level objectives in the NIST Cybersecurity Framework as well as cyber frameworks from the Payment Card Industry, International Organization for Standardization, and Institute of Electrical and Electronics Engineers. The State of California has already identified the CIS Controls as an expected practice for companies doing business within the state. The CIS Controls are available as a free download here.

“Organizations will continue to be at risk for cyber-attacks and breaches, but the solution is not rocket science; it's basic cyber hygiene like patching and scanning,” said Sager.

The CIS Controls and CIS Benchmarks are a global standard and stated best practices for securing IT systems and data against the most pervasive attacks. The proven guidelines are continuously refined and verified by a volunteer, global community of experienced IT professionals. CIS is home to the Multi-State Information Sharing & Analysis Center (MS-ISAC), the go-to resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities.


Ken Briodagh is a writer and editor with more than a decade of experience under his belt. He is in love with technology and if he had his druthers would beta test everything from shoe phones to flying cars.

Edited by Ken Briodagh
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Editorial Director

SHARE THIS ARTICLE
Related Articles

Assessing IoT Innovator LTIMindtree: Its 2023-24 Successes to Date and a Peek at What's Next

By: Alex Passett    4/24/2024

IoT Evolution World has presented a brief rundown of LTIMindtree's successes during FY24, as well as a peek at what's to come for the Internet of Thin…

Read More

Powering Adaptability in IoT: Telit Cinterion Reveals its First High-Precision GNSS Module

By: Alex Passett    4/22/2024

Telit Cinterion announced the launch of its SE868K5-RTK module, a high-precision Global Navigation Satellite System (GNSS) receiver capable of centime…

Read More

ICYMI: Your 'IoT TGIF' News Review

By: Alex Passett    4/19/2024

We've compiled several Internet of Things (IoT) stories that will benefit readers interested in global IoT market growth, Industrial Internet of Thing…

Read More

Tracking the Growth of IoT: Global Industry Revenue, Uses Cases, and Security for What's Next

By: Alex Passett    4/18/2024

Citing data from the likes of Stocklytics, Statista and Earthweb, further study of the rapidly evolving Internet of Things is always recommended.

Read More

ICYMI: Your Weekly IoT News Review

By: Alex Passett    4/12/2024

We've compiled a handful of important Internet of Things (IoT) news stories that will benefit readers interested in consumer-facing developments, indu…

Read More